|[Front page] [Index]|
The Online Certificate Status Protocol (OCSP) can be used to provide online certificate status information for the end entities within the PKI. OCSP can be seen as a replacement for CRL, and it may be a more appropriate method in environments where signatures of individual transactions need to be validated with up-to-date revocation information.
The OCSP Responder Service of SSH Tectia Certifier can be used to answer clients' status requests concerning one or more of the Certifier CAs. Currently the OCSP responder can provide status information only for those certificates that are issued by CAs that are managed within the Certifier installation.
Service description is a free-form description of the Service and its function.
Service status can be either Active or Disabled. If the service is Disabled, it does not perform its function. This option can be used to take the service temporarily out of use.
Service bind address is an HTTP URL, since OCSP uses HTTP as a transport mechanism.
If the check box under Allowed operations is selected, an OCSP client can request status information without signing the request.
The OCSP responder needs to have a private key and a certificate, so that end entities can validate the signed OCSP responses. Once the OCSP Responder Service is created, the private key is generated and the responder certificate enrolled. Select the CA from which the OCSP responder certificate is enrolled using the Responder CA field.
The validity period included in the certification request can be selected using the Validity period length field.
The length of the OCSP responder private key (measured in number of bits used) can be chosen with the Key size option.
External URL address is the URL that will be included in the authority information extension field of the issued end-entity certificates, if the extension is included in the CA policy. End entities will use this field to connect to the OCSP responder. This definition can be left empty, in which case the Service bind address field is used as a default value. However, please note that this address must be accessible from all clients using OCSP, so a different address might be wanted here.
Once the certificate for the Service has been enrolled, Certificate status shows its status, and the certificate can be viewed by clicking View Certificate.
Click the Continue button to accept changes made to the Service settings, or click Cancel to discard them. After clicking Continue, remember to Commit Changes on the Edit Server Entity page.